Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2022-40842
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
Ndkadvancedcustomizationfields
after 3.5.0
MEDIUM 6.5
CVE-2022-4096
Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.
Appsmith
1.8.2+
HIGH 8.8
CVE-2022-41609
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.
Better Messages
1.9.10.69+
HIGH 8.8
CVE-2022-43183
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Xxl Job
after 2.3.1
HIGH 7.5
CVE-2022-42894
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerabilit…
Syngo Dynamics Cardiovascular Imaging And Information System
Mitigation only
HIGH 7.5
CVE-2022-43140
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#g…
Kkfileview
No fix yet
MEDIUM 6.5
CVE-2022-39383
KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm C…
Kubevela
1.5.9 / 1.6.2+
HIGH 8.7
CVE-2022-41906
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Cu…
Opensearch Notifications
2.2.1.0+
MEDIUM 6.5
CVE-2022-42494
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
All In One Seo
after 4.2.5.1
MEDIUM 6.5
CVE-2022-20951
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perf…
Broadworks Messaging Server
23.0+
HIGH 8.8
CVE-2022-20958
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to pe…
Broadworks Commpilot Application
23.0+
MEDIUM 5.3
CVE-2022-39276
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk feat…
Glpi
10.0.4+
CRITICAL 9.8
CVE-2022-41552
Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe compone…
Infrastructure Analytics Advisor
10.9.0-00+
CRITICAL 9.8
CVE-2022-40296
The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potential…
Php Point Of Sale
Mitigation only
HIGH 8.1
CVE-2022-3708
The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.0 due to insufficient validat…
Web Stories
1.25.0+
MEDIUM 6.5
CVE-2022-43776
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously impl…
Metabase
0.44.5+
HIGH 8.8
CVE-2022-36451
A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server…
Micollab
after 9.5.0.101
HIGH 7.5
CVE-2022-41704
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri…
Batik
1.16+
HIGH 7.5
CVE-2022-42890
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML …
Batik
1.16+
MEDIUM 6.5
CVE-2022-3247
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure…
Blog2social
6.9.10+
CRITICAL 9.8
CVE-2022-38580EPSS 11%
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
Skipper
0.13.237+
MEDIUM 5.3
CVE-2022-39055
RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover…
Rava Certificate Validation System
Mitigation only
CRITICAL 9.8
CVE-2022-42149
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
Kkfileview
Mitigation only
CRITICAL 9.1
CVE-2022-41477
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attack…
Webid
after 1.2.2
CRITICAL 9.8
CVE-2022-41496
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
Icms
No fix yet
CRITICAL 9.8
CVE-2022-41497
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
Clippercms
No fix yet
CRITICAL 9.8
CVE-2022-41495
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
Clippercms
No fix yet
MEDIUM 6.5
CVE-2022-36551EPSS 5%
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authe…
Label Studio
after 1.5.0
HIGH 8.8
CVE-2022-41040 KEVEPSS 100%
Microsoft Exchange Server Elevation of Privilege Vulnerability
Exchange Server
Patch available
MEDIUM 6.5
CVE-2022-35282
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, …
Websphere Application Server
7.0.0.45 / 8.0.0.15+